Back to Browse

Datapass Verify MCP Server

Developer ToolsLow Risk10.0MCP RegistryRemote
Free

Server data from the Official MCP Registry

Neutral escrow for customer-data offboarding (GDPR/EU Data Act): query MyDataPass facts.

About

Neutral escrow for customer-data offboarding (GDPR/EU Data Act): query MyDataPass facts.

Remote endpoints: streamable-http: https://mcp.mydatapass.app/api/mcp

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (1 strong, 0 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry.

5 tools verified · Open access · No issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "io-github-mydatapass-mydatapass": {
      "url": "https://mcp.mydatapass.app/api/mcp"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

mydatapass-verify

Independently verify a MyDataPass export — without trusting us.

MyDataPass delivers customer data offboarding exports as encrypted, audit-logged packages. This repository contains everything a recipient (or their security team) needs to decrypt and verify an export with zero MyDataPass involvement: the package format specification and two standalone verifiers.

Why this repo exists

Our security model does not rely on secrecy of the format — it relies on the strength of the passphrase and standard, auditable cryptography. Publishing the format and the verification tooling means:

  • Your security team can review exactly how packages are encrypted before signing anything.
  • Recipients can decrypt and verify integrity offline, with no DataPass servers involved.
  • If DataPass disappeared tomorrow, every delivered package would remain fully recoverable with the passphrase and this tooling.

What's in an export package

A MyDataPass package is a JSON file with four fields:

FieldDescription
ciphertext_b64AES-256-GCM ciphertext, Base64
iv_b6412-byte random nonce, Base64
salt_b6416-byte random KDF salt, Base64
hash_sha256SHA-256 hex digest of the original plaintext

Encryption: AES-256-GCM. Key derivation: PBKDF2-HMAC-SHA256, 310,000 iterations, 32-byte key. Full details in docs/export-format.md.

Verify an export

Option A — browser, fully offline

Open verify.html in any modern browser (works from file://, no network requests are made). Select the package file, enter the passphrase, and the page decrypts via WebCrypto and checks the SHA-256 digest locally.

Option B — command line

Requires Python 3.9+ and the cryptography package:

pip install cryptography
python verify.py package.json --out exported-data.bin

The script prompts for the passphrase, decrypts, and confirms the plaintext digest matches hash_sha256. Exit code 0 means the package is authentic and intact; any tampering with the ciphertext fails GCM authentication.

What this repo is NOT

This is not the MyDataPass product source code. It is the public, auditable surface: the delivery format, the verification tooling, and our security model. Questions or responsible disclosure: silvia@mydatapass.pro.

License

MIT — see LICENSE.

Reviews

No reviews yet

Be the first to review this server!